HIPAA Security Rule Updates 2025: What Healthcare Professionals Need to Know

    February 11, 202613 min read
    HIPAA Security Rule Updates 2025: What Healthcare Professionals Need to Know

    HIPAA Security Rule Updates 2025: What Healthcare Professionals Need to Know

    The healthcare industry faces unprecedented cybersecurity challenges. With the average cost of a healthcare data breach exceeding $10 million and hacking incidents at historic highs, the U.S. Department of Health and Human Services has proposed the most significant overhaul of HIPAA security requirements in over a decade. Published as a Notice of Proposed Rulemaking on January 6, 2025, these updates shift from flexible, “addressable” safeguards to mandatory requirements that will fundamentally change how healthcare organizations protect patient information.

    For healthcare professionals responsible for patient data—whether office managers, compliance staff, or clinical administrators—understanding these changes is critical. The proposed updates close longstanding gaps that cybercriminals have exploited and align HIPAA with modern security standards. While the final rule is expected in late 2025 or early 2026, organizations should begin preparing immediately to meet the anticipated 180-day compliance window.

    This guide explains the key changes in practical terms, focusing on what healthcare professionals need to know and do, regardless of technical background.

    Understanding the Shift from Addressable to Mandatory Requirements

    The current HIPAA Security Rule categorizes safeguards as either “required” or “addressable.” Many organizations have misunderstood “addressable” to mean optional, when it actually means organizations must implement the control or document a reasonable alternative. This ambiguity created inconsistent security practices across the healthcare industry.

    The 2025 updates eliminate most addressable designations, making critical safeguards mandatory. This change removes flexibility but also removes confusion. Organizations can no longer justify skipping essential protections like encryption or multi-factor authentication based on budget constraints or operational convenience.

    Office of Inspector General audits revealed widespread gaps in current compliance, with many covered entities failing to implement basic security measures. The proposed updates address these deficiencies by establishing clear, non-negotiable requirements that reflect established cybersecurity best practices.

    Key Changes Healthcare Organizations Must Address

    Multi-Factor Authentication Becomes Mandatory

    Perhaps the most impactful change is the requirement for multi-factor authentication (MFA) on all systems that access electronic protected health information. MFA requires users to verify their identity using at least two different factors—typically something they know (password) and something they have (smartphone app or hardware token).

    The proposal specifically prohibits SMS-based authentication for HIPAA compliance due to known security vulnerabilities. Healthcare organizations must implement app-based authenticators, hardware tokens, or biometric verification instead.

    Many healthcare professionals worry that MFA will slow down clinical workflows, particularly during emergencies. However, modern MFA solutions offer streamlined options that add only seconds to the login process. Organizations should prioritize implementation on electronic health record systems, email, and cloud-based applications first, then expand to other systems.

    Practical implementation considerations:

    • Choose authenticator apps compatible with existing devices and systems
    • Establish bypass procedures for true emergencies with detailed logging
    • Train staff during low-volume periods to minimize disruption
    • Allow grace periods for users to register devices before enforcement
    • Provide technical support during the initial rollout phase

    Encryption Requirements Expand and Strengthen

    Under current rules, encryption of data at rest and in transit is addressable. The proposed updates make encryption mandatory in virtually all circumstances. This applies to ePHI stored on servers, workstations, mobile devices, removable media, and data transmitted across networks.

    Healthcare organizations must implement industry-standard encryption protocols. For data in transit, this means TLS 1.2 or higher for network communications. For data at rest, this requires full-disk encryption on devices and encryption of databases containing ePHI.

    Small practices often express concerns about the cost and complexity of encryption. However, modern operating systems include built-in encryption tools. Windows offers BitLocker, macOS includes FileVault, and most email services support encrypted transmission by default. The technical burden is considerably lower than many organizations assume.

    Organizations should inventory all locations where ePHI exists—including backup systems, archived data, and portable devices—and verify encryption status. Any gaps represent immediate priorities for remediation.

    Asset Inventory and Data Mapping Requirements

    The proposed rule mandates annual inventories of all hardware and software assets that process, store, or transmit ePHI. This includes servers, workstations, mobile devices, applications, cloud services, and network equipment. Organizations must also maintain data flow maps showing how ePHI moves through systems and to third parties.

    These requirements address a fundamental security principle: organizations cannot protect what they do not know they have. Many breaches occur because organizations lost track of systems containing sensitive data or failed to update legacy equipment.

    Creating an asset inventory without technical expertise:

    • Start with obvious systems like electronic health records and billing software
    • Interview department heads to identify specialized applications
    • Review vendor contracts to identify cloud services and business associates
    • Document network-connected medical devices and diagnostic equipment
    • Include workstations, laptops, tablets, and smartphones that access ePHI
    • Update the inventory when new systems are added or old systems retired

    For data mapping, trace patient information from collection through storage, transmission, and disposal. Document which systems connect to each other, where data is backed up, and which vendors receive ePHI. Simple flowcharts or spreadsheets satisfy this requirement for most small to medium organizations.

    Continuous Risk Analysis Replaces Annual Assessments

    Current HIPAA requirements call for periodic risk analyses, typically interpreted as annual reviews. The proposed updates require continuous risk assessment and management. Organizations must identify and evaluate risks on an ongoing basis rather than once per year.

    This shift reflects the reality that cyber threats do not operate on annual cycles. New vulnerabilities emerge constantly, and organizations need real-time awareness of their security posture. Continuous risk assessment does not necessarily require expensive automated tools, though such tools can help.

    For organizations with limited budgets, continuous risk assessment can be implemented through:

    • Quarterly self-assessments using standardized checklists
    • Monthly review of security logs and alerts
    • Immediate assessment when new systems are deployed or threats emerge
    • Regular vulnerability scanning using available tools
    • Documentation of risk decisions and mitigation actions

    Maintain a risk register that tracks identified risks, their likelihood and impact, mitigation measures, and current status. Update this register whenever circumstances change rather than waiting for an annual review cycle.

    Enhanced Vulnerability Testing and Penetration Testing

    The proposed rule requires vulnerability scans at least every six months and annual penetration testing. Vulnerability scanning identifies known security weaknesses in systems, while penetration testing simulates real-world attacks to find exploitable flaws.

    These requirements formalize best practices already followed by security-conscious organizations. Regular testing identifies problems before attackers exploit them. However, many healthcare organizations have never conducted formal testing, particularly penetration testing, due to cost concerns.

    Budget-conscious approaches to testing requirements:

    • Use free or low-cost vulnerability scanning tools for initial assessments
    • Focus penetration testing on internet-facing systems and critical infrastructure
    • Consider cooperative arrangements with academic programs that need practice environments
    • Leverage managed service providers that include testing in service packages
    • Document all testing activities and remediation efforts in detail

    Organizations cannot ignore findings. The rule emphasizes timely remediation of identified vulnerabilities based on risk severity. Critical vulnerabilities in internet-facing systems demand immediate attention, while lower-risk issues may be addressed through scheduled maintenance cycles.

    Accelerated Access Termination Procedures

    When workforce members leave or change roles, organizations must revoke their access to ePHI within one hour under the proposed updates. This dramatically tightens current practices, where access termination often takes days or weeks.

    The one-hour requirement recognizes that departing employees represent elevated security risks, whether through malicious intent or accidental access using outdated credentials. Prompt deactivation limits opportunities for data theft or sabotage.

    Implementation requires coordination between human resources, IT, and department managers. Effective procedures include:

    • Standardized termination checklists that include all systems and access points
    • Automated account deactivation tied to HR systems where possible
    • Clear communication channels for urgent termination notifications
    • Regular audits of active accounts to identify orphaned credentials
    • Documentation of termination timing for compliance verification

    Small organizations without dedicated IT staff should establish simple protocols that designated staff can execute immediately upon notification of termination or role change.

    Strengthened Business Associate Requirements

    Third-party vendors that handle ePHI on behalf of covered entities are business associates under HIPAA. The proposed updates significantly strengthen requirements for managing business associate relationships, making covered entities more accountable for their vendors’ security practices.

    Organizations must conduct due diligence before engaging business associates, verify their security capabilities, and monitor their compliance on an ongoing basis. Business associate agreements must include specific security requirements aligned with the updated Security Rule.

    Practical vendor management for non-technical staff:

    • Develop standard questionnaires asking vendors about encryption, MFA, backup procedures, and incident response capabilities
    • Request evidence of security measures such as SOC 2 reports or security certifications
    • Update business associate agreements to reflect mandatory security controls
    • Establish risk-based monitoring schedules with high-risk vendors reviewed quarterly and lower-risk vendors reviewed annually
    • Maintain vendor contact information for breach notification purposes

    Organizations should prioritize vendors based on the sensitivity and volume of ePHI they handle. A cloud-based EHR provider represents higher risk than a shredding service and deserves more intensive oversight.

    Session Timeout and Security Configuration Standards

    The proposed rule introduces specific technical requirements previously left to organizational discretion. These include mandatory session timeouts for inactive users and security configuration standards for systems processing ePHI.

    Session timeouts automatically log users out after a defined period of inactivity, reducing the risk of unauthorized access through unattended workstations. While the exact timeout duration is not specified, industry standards typically range from 10 to 30 minutes depending on the environment and sensitivity of data.

    Security configuration standards require organizations to implement vendor-recommended security settings or industry benchmarks such as those published by the Center for Internet Security. Default configurations often prioritize ease of use over security, leaving systems vulnerable to attack.

    Implementation guidance:

    • Configure session timeouts in electronic health records and other applications
    • Enable automatic screen locks on workstations after brief periods
    • Apply security configuration baselines to all new systems before deployment
    • Document any deviations from recommended configurations with justification
    • Review configurations after software updates that might reset security settings

    These technical controls work in conjunction with policies and procedures to create defense in depth—multiple layers of security that protect ePHI even if individual controls fail.

    Emerging Requirements for Artificial Intelligence Governance

    The proposed updates represent the first time HIPAA regulations explicitly address artificial intelligence technologies. As healthcare organizations increasingly adopt AI for diagnosis support, administrative automation, and research, these tools introduce new privacy and security considerations.

    The proposal recommends establishing AI steering committees to oversee responsible AI use and developing policies for AI systems that process ePHI. These governance structures should evaluate AI tools for compliance with HIPAA requirements before deployment and monitor their ongoing use.

    Practical AI governance for early adopters:

    • Form a cross-functional committee including compliance, clinical, IT, and administrative representatives
    • Develop policies addressing vendor selection, risk assessment, and acceptable use cases
    • Require vendors to document security controls and HIPAA compliance measures
    • Assess AI systems for potential bias that might affect patient care
    • Establish procedures for human review of AI-generated recommendations
    • Document decisions about AI tool approval or rejection

    Organizations not currently using AI should establish policies proactively, as vendors increasingly embed AI features into existing healthcare applications. Clear governance frameworks enable organizations to adopt beneficial technologies while maintaining compliance.

    Preparing for Compliance Before the Final Rule

    Although the final rule has not been published, healthcare organizations should begin preparation immediately. The proposed requirements reflect widely recognized security best practices that improve security regardless of regulatory mandates.

    Priority actions for immediate implementation:

    • Conduct a gap analysis comparing current practices to proposed requirements
    • Inventory assets and create data flow maps
    • Implement multi-factor authentication on high-priority systems
    • Verify encryption status for all ePHI storage and transmission
    • Update business associate agreements to include enhanced security requirements
    • Establish or update risk registers with continuous monitoring processes
    • Schedule vulnerability assessments and penetration testing
    • Review and tighten access termination procedures

    Organizations should document all preparation activities. This documentation demonstrates good faith efforts toward compliance and provides evidence of a robust security program even before requirements become mandatory.

    The comment period closed in March 2025, with final rule publication expected in late 2025 or early 2026. Once published, covered entities will likely receive a 180-day implementation period. Organizations that begin preparation now will face less scrambling when compliance deadlines arrive.

    Common Misconceptions About the Updated Requirements

    Several misunderstandings about the proposed updates can lead organizations astray.

    Misconception: Addressable controls were optional under previous rules. In reality, addressable controls required implementation or documented equivalent alternatives. The updated rule simply makes expectations explicit.

    Misconception: Small practices are exempt from requirements. HIPAA applies to all covered entities regardless of size. Small practices may implement controls differently than large hospitals, but they must meet the same fundamental requirements.

    Misconception: Compliance guarantees security. HIPAA establishes minimum standards, not comprehensive security. Organizations should view compliance as a baseline and implement additional protections based on their specific risk environment.

    Misconception: Technology alone ensures compliance. The Security Rule requires administrative, physical, and technical safeguards working together. Policies, training, and physical access controls are equally important as firewalls and encryption.

    Misconception: Annual audits satisfy continuous risk assessment requirements. Effective risk management requires ongoing attention to emerging threats, not annual checkboxes.

    Understanding these distinctions helps organizations approach compliance appropriately and avoid false confidence from partial implementations.

    Building a Sustainable Compliance Program

    The updated HIPAA Security Rule presents an opportunity to strengthen healthcare cybersecurity fundamentally. Rather than viewing requirements as burdens, organizations should recognize them as structured frameworks for protecting patient information and organizational reputation.

    Sustainable compliance programs integrate security into daily operations rather than treating it as a separate compliance exercise. When security becomes part of normal workflow, it becomes more effective and less burdensome.

    Key principles for sustainable programs:

    • Assign clear responsibility for security tasks and compliance monitoring
    • Integrate security considerations into procurement, deployment, and operations
    • Provide regular training tailored to staff roles and responsibilities
    • Establish simple reporting mechanisms for security concerns and incidents
    • Maintain documentation that supports both compliance and operational improvement
    • Review and update security measures as technology and threats evolve

    Organizations with limited resources should focus on fundamentals first: strong authentication, encryption, access controls, and vendor management. These controls address the most common attack vectors and satisfy core HIPAA requirements.

    Moving Forward with Confidence

    The proposed HIPAA Security Rule updates represent significant changes, but they are manageable with proper planning and prioritization. Healthcare professionals without technical backgrounds can implement many requirements through procedural controls, vendor management, and structured processes.

    Understanding the rationale behind requirements helps organizations implement them effectively rather than simply checking compliance boxes. Each requirement addresses real vulnerabilities that attackers actively exploit. Implementation protects patients, preserves organizational reputation, and reduces the risk of costly breaches and penalties.

    Organizations should monitor HHS communications for final rule publication and implementation guidance. Industry associations and security communities will provide additional resources as implementation deadlines approach.

    The healthcare industry’s increasing reliance on digital systems makes strong cybersecurity essential. The updated HIPAA Security Rule provides a roadmap for meeting this challenge. Organizations that approach compliance thoughtfully will emerge with stronger security postures that benefit patients, staff, and the organization as a whole.

    Share this article

    Enjoyed this article?

    Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.

    A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.

    No spam. Unsubscribe anytime.

    Prefer to Listen?

    Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.

    Listen on Spotify